VibeGuard: Academic Security Framework for AI-Generated Code, Motivated by Claude Code Source Map Leak
arXiv·high signal
Proposes a security gate framework for 'vibe coded' applications where developers accept AI output with minimal review. Directly motivated by the March 31 Claude Code npm source map incident that exposed 512K lines of proprietary TypeScript. Existing SAST and secret-scanning tools fail on AI-generated code patterns. Framework addresses packaging misconfigurations, embedded secrets, and dependency confusion specific to AI-assisted development workflows.